Executive brief
A vulnerability exists in Oracle Teleservice, a customer service management module within the Oracle E-Business Suite. An unauthenticated attacker could remotely access the system to view, modify, or delete certain service-related data. This could lead to unauthorized changes to customer records or the exposure of sensitive service information without requiring any user interaction.
Technical details
A vulnerability in the Service Diagnostics Scripts component of Oracle Teleservice (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a partial loss of confidentiality and integrity, as the attacker can read, insert, update, or delete a subset of data accessible to the Teleservice module. Affected versions include 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Teleservice 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory